The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and other government partners and agencies have released a Cybersecurity Advisory to warn of an active cyber threat to internet-exposed Siemens S7 Series programmable logic controllers (PLCs).
However, the advisory also notes that they have observed similar threat activity beyond the Siemens PLCs, and recommends owners and operators consider applying the mitigations to other applicable devices and systems.
Primary mitigations include:
• Inventory all Siemens S7 Series PLCs
• Apply critical security patches
• Ensure PLCs are not accessible from the internet
• Strengthen access controls
• Monitor for unauthorized activity
• Harden PLC services, protocols, and ladder logic integrity
• Hunt for anomalies that may indicate a compromise.
